1. CVE-2020-17049 Kerberos Bronze Bit 攻击:实战利用 netspi.com | 漏洞 | 2020-12-08 00:00 | 原文 ↗ | #active-directory | #kerberos | #red-team | #constrained-delegation CVE-2020-17049 实战利用:掌握服务账户密码哈希后,攻击者可绕过 Protected Users 组与 TrustedToAuthForDelegation 限制,沿 Kerberos 委派路径实施横向移动,补丁分批推送至 2021 年 2 月。
2. CVE-2020-17049 Kerberos Bronze Bit 攻击:概述 netspi.com | 漏洞 | 2020-12-08 00:00 | 原文 ↗ | #active-directory | #kerberos | #windows | #constrained-delegation CVE-2020-17049(Bronze Bit)攻击原理概述:攻击者利用 Kerberos 约束委派缺陷篡改服务票据的 forwardable 标志位,进而冒充 Protected Users 组等被标记为禁止委派的敏感用户。
3. CVE-2020-17049: Kerberos Bronze Bit Attack – Theory netspi.com | 漏洞 | 2020-12-08 00:00 | 原文 ↗ | #active-directory | #kerberos | #red-team | #delegation Kerberos Bronze Bit 攻击(CVE-2020-17049)原理剖析:利用 KDC 在推导服务密钥时的缺陷绕过委派权限检查,配合基于资源的约束委派(RBCD)攻击 Active Directory。